AI Governance, Risk & Red Teaming
Aware · M9 · lesson 9 of 18 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
The Four Risk Tiers and the Annex III Eight
📖
now learning

The Four Risk Tiers and the Annex III Eight

15 min

If Article 3(1) is the bouncer at the front door of the EU AI Act, the risk-tier classification is the elevator that decides which floor your system lands on. There are exactly four floors, prohibited (Article 5), high-risk (Article 6 + Annex III), limited / transparency (Article 50), and the residual minimal-risk tier, and each one carries a very different bill of materials. Get the elevator button wrong and the rest of your compliance program either over-spends in the lobby or finds itself answering a regulator's letter from a floor it didn't know it was on. This lesson is how the elevator works in 2026, what each floor actually contains, and how a Responsible AI Officer produces the tiering memo that the AI Officer, the General Counsel, and the notified body all read on the same Monday morning.

Why the Tier Decision Decides Everything Downstream

Almost every dollar of EU AI Act compliance spend keys off the risk-tier classification. The prohibited tier is a hard stop: Article 5 lists practices that cannot be placed on the market or put into service under any conditions, with Article 99(2) backing that at up to €35 million or 7% of global annual turnover, whichever is higher. The high-risk tier is the entire engine of the regulation: Article 6 plus Annex III routes you into the Article 9 risk-management system, the Article 10 data governance regime, Article 11 plus Annex IV technical-file work, Article 14 human-oversight design, Article 15 accuracy / robustness / cybersecurity claims, Article 17 quality-management system, Article 26 deployer obligations, Article 27 fundamental-rights impact assessment for public bodies and credit/insurance deployers, Article 43 conformity-assessment decision, Article 47 declaration of conformity, Article 71 EU database registration, Article 72 post-market monitoring program, Article 73 serious-incident reporting clock, and the notified-body bottleneck under Article 31. The limited / transparency tier is comparatively cheap, Article 50 disclosures and watermarking. Residual minimal-risk is cheap by design, Article 4 literacy plus horizontal obligations.

The cost delta is enormous. A high-risk classification often adds a six-figure compliance bill per system in the first twelve months: notified-body engagement fees, FRIA artifacts, post-market monitoring infrastructure, QMS standup, Annex IV file, literacy program for affected workers, documentation flow-down from upstream GPAI providers. A limited-risk classification of the same system might add €15,000 in disclosure copy and a watermarking integration. Minimal-risk might add a paragraph in the AI literacy curriculum and a row in the inventory. The tiering memo is the single most consequential paper artifact in the L1 program.

And here is the trap: tier classification is not a single decision. It is a sequence of decisions, in a specific order, with carve-outs and overlays at every step. The order matters; the carve-outs matter; the overlays matter. A scope memo that classifies a system as "minimal-risk" without walking the sequence is not a defensible artifact. It is a guess in a tidy spreadsheet column. This lesson teaches you the sequence.

The Tiering Sequence - Five Questions in Order

For every in-scope system that cleared Article 3(1), the Responsible AI Officer asks five questions in order. Answer "yes" to a question and you have your tier; the questions below it do not apply. Answer "no" to all five and the system lands in the residual minimal-risk bucket. Here is the sequence, with the article hooks named:

  1. Is the practice prohibited under Article 5? If yes, stop, do not deploy. Penalty exposure: Article 99(2), up to €35 million or 7% of global turnover.
  2. Is the system covered by Article 6(1). I.e., an AI system that is a safety component of, or itself a product covered by, the harmonized Union legislation listed in Annex I, where that product is subject to third-party conformity assessment? If yes, high-risk on the Annex I embedded-product track (Aug 2, 2028 applicability under Omnibus VII for new placements; legacy carve-outs apply).
  3. Does the system fall within one of the eight Annex III categories under Article 6(2)? If yes, high-risk on the stand-alone Annex III track (Dec 2, 2027 applicability under Omnibus VII; FRIA capability and operational readiness expected earlier).
  4. Does Article 6(3) apply. I.e., is the Annex III system a narrow-task system that does not pose a significant risk? If yes: the provider self-assesses out of the high-risk tier, documents the rationale, and registers under Article 49(2). The system stays in scope but moves to whichever lower tier applies.
  5. Does Article 50 apply: does the system interact with natural persons, generate synthetic content, or otherwise trigger a transparency obligation? If yes, limited / transparency tier (Article 50(1) chatbot disclosure applies on first use; Article 50(2) machine-readable marking applies from Dec 2, 2026 under Omnibus VII; Article 50(4) deepfake / generated-content labelling applies).

If none of the five gates fire, the system lands in the residual minimal-risk tier: Article 4 literacy, voluntary codes of conduct under Article 95, and whatever else the organization has chosen to commit to. The residual tier still belongs in the inventory and the literacy program. It is not "unregulated". It is "regulated only by the horizontal obligations." That distinction is what keeps the audit committee from being surprised.

Floor 1 - The Article 5 Prohibited Practices

Article 5 lists eight categories of AI practice that are forbidden in the Union. The list has been refined through the trilogue and Commission guidance and now reads, in operational paraphrase:

  • Article 5(1)(a): Subliminal techniques beyond a person's consciousness, or purposefully manipulative or deceptive techniques, with the objective or effect of materially distorting behavior in a way that is reasonably likely to cause significant harm. The classic example is a subliminal-cue marketing system that pushes vulnerable users toward gambling addiction.
  • Article 5(1)(b): Exploitation of the vulnerabilities of natural persons due to age, disability, or specific social or economic situation. The example: a debt-collection chatbot that pressures users in financial distress.
  • Article 5(1)(c): Social scoring by public authorities or on their behalf, where the score leads to detrimental or unfavorable treatment in contexts unrelated to the source data, or treatment that is unjustified or disproportionate.
  • Article 5(1)(d), Real-time predictive policing based solely on profiling or assessment of personality traits. (Narrow carve-outs exist for individualized assessments based on objective and verifiable facts.)
  • Article 5(1)(e), Untargeted scraping of facial images from the internet or CCTV to build or expand facial-recognition databases. The Clearview AI use case is the named target here.
  • Article 5(1)(f), Emotion recognition in workplaces and educational institutions, with carve-outs for medical or safety reasons.
  • Article 5(1)(g): Biometric categorization of natural persons to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation. Limited carve-outs exist for lawful filtering of datasets and law enforcement.
  • Article 5(1)(h), Real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, except in narrowly enumerated cases (e.g., targeted search for a victim of a specific crime, prevention of substantial and imminent threat to life, prosecution of certain serious crimes), and only with prior authorization.

The practical takeaway for an enterprise deployer: most prohibited-tier exposure comes from three patterns. First, vendor-bundled "emotion AI" features in workplace productivity tools (CRM, sales-call coaching, video-conferencing) that quietly fall under Article 5(1)(f). Second, "personalized" engagement features in consumer-facing AI that drift toward Article 5(1)(a) manipulation in edge cases. Third, biometric-categorization in retail-analytics or in-store cameras that drift toward Article 5(1)(g). Procurement is the canonical point of failure; the tiering memo is the canonical defense.

The audit-committee question always follows: "How do we know we don't have any of these?" The answer is an Article 5 negative-assurance review across the AI inventory, a one-paragraph attestation per system that names each of the eight 5(1) sub-paragraphs and explains why the system does not implicate it. It takes a day at the start, and it is the cheapest insurance the organization buys. Skipping it is the most expensive shortcut on the L1 menu.

Floor 2 - The High-Risk Tier: Article 6, Annex I, and Annex III

High-risk is the engine of the EU AI Act. Article 6 routes systems into the high-risk tier through two doors:

Article 6(1) - Annex I embedded products. A system is high-risk if it is a safety component of, or is itself, a product covered by the harmonized Union legislation listed in Annex I (machinery, toys, lifts, radio equipment, medical devices, in-vitro diagnostic medical devices, civil aviation, vehicles, marine equipment, rail systems, agricultural and forestry vehicles, recreational craft, cableway installations, gas appliances, equipment in potentially explosive atmospheres, pressure equipment, personal protective equipment), AND that product is subject to a third-party conformity assessment under that legislation. The Omnibus VII political agreement of May 7, 2026 moved the stand-alone applicability of these Annex I high-risk obligations to Aug 2, 2028 from the original Aug 2, 2027. The substantive obligations otherwise mirror the Annex III obligations: same Annex IV file, same Article 9 risk-management system, same Article 17 QMS, integrated into the existing harmonized-product conformity machinery.

Article 6(2) - Annex III stand-alone systems. A system is high-risk if it falls within one of the eight Annex III categories. Under Omnibus VII (May 7, 2026 political agreement), the stand-alone applicability of these obligations moved from Aug 2, 2026 to Dec 2, 2027. The eight Annex III categories, in operational paraphrase:

Annex III §1 - Biometrics

Includes remote biometric-identification systems (other than the Article 5(1)(h) prohibited use), biometric-categorization systems based on sensitive or protected attributes (Article 5(1)(g) prohibits the deductive use; non-prohibited categorization may still be high-risk), and emotion-recognition systems outside the workplace/education prohibition. The example: a border-control biometric matching system; a retail-analytics camera that infers age-band and gender for demographic reporting (with careful Article 5(1)(g) review).

Annex III §2 - Critical Infrastructure

AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating, and electricity. The example: an AI-based load-balancing system for a regional electricity grid; an AI-based control loop in a water treatment plant; an AI system that prioritizes road-traffic signal phasing in a smart-city deployment.

Annex III §3 - Education and Vocational Training

Systems used to determine access or admission to educational institutions, to evaluate learning outcomes, to assess the appropriate level of education, and to detect prohibited behavior during tests (proctoring). The example: an AI-based application-review tool used by a university; an AI-based proctoring tool used during certification exams; an AI-based adaptive-learning placement engine. NYC LL 144 has a related-but-separate U.S. analog for hiring.

Annex III §4: Employment, Workers' Management, and Access to Self-Employment

The big enterprise category. Systems used to recruit or select natural persons (resume screening, candidate ranking, interview analysis), to make decisions about promotion or termination, to allocate tasks based on individual behavior or personal traits, or to monitor and evaluate performance and behavior. Almost every HR-tech vendor sells here; almost every internal HR-data-science build sits here. NYC Local Law 144 and Texas TRAIGA HB 149 have related U.S. analogs.

Annex III §5 - Essential Private and Public Services

Five sub-categories: (a) public-assistance benefits and services; (b) creditworthiness scoring and credit-score evaluation (carve-out for detecting financial fraud); (c) life and health insurance risk assessment and pricing; (d) dispatching or prioritizing emergency-response services; (e) public services such as access to those services. The credit / insurance sub-categories §5(b) and §5(c) carry the additional Article 27 FRIA obligation for any deployer regardless of public/private status.

Annex III §6 - Law Enforcement

Systems used by or on behalf of law-enforcement authorities to: assess the risk of a natural person becoming a victim or perpetrator of a criminal offense; act as a polygraph or similar tool; evaluate the reliability of evidence; predict the occurrence or recurrence of an actual or potential criminal offense based on profiling; or profile natural persons in the course of detection, investigation, or prosecution of criminal offenses. Tight constraints on use; many Member States have additional national rules.

Annex III §7 - Migration, Asylum, and Border Control

Systems used as polygraphs or similar; to assess risks posed by a natural person intending to enter the territory; to assist with examining applications for asylum, visa, or residence permits; or to detect, recognize, or identify natural persons in the migration context. Limited deployer base in the private sector but central for government and contractor work.

Annex III §8 - Administration of Justice and Democratic Processes

Systems used to assist a judicial authority in researching and interpreting facts and the law and applying the law to a concrete set of facts, or used in influencing the outcome of an election or referendum or the voting behavior of natural persons (carve-out for tools that organize, optimize, or structure political campaigns from an administrative or logistical perspective).

The Annex III Applicability Moves Under Omnibus VII

This is the most consequential 2026 change for the tiering memo. The Omnibus VII political agreement of May 7, 2026, reached by the Council and the European Parliament, moved the stand-alone Annex III applicability date from Aug 2, 2026 to Dec 2, 2027. The Annex I embedded-product applicability date moved from Aug 2, 2027 to Aug 2, 2028. The Article 50(2) machine-readable marking grace period was cut, bringing it forward to Dec 2, 2026. GPAI enforcement powers remain on the Aug 2, 2026 track, Omnibus VII did not move that date.

What this means for the tiering memo in May 2026:

  • The high-risk obligations did not disappear. They moved. The Annex IV technical file, the Article 9 RMS, the Article 17 QMS, the Article 27 FRIA, the Article 47 declaration, the Article 71 registration, the notified-body engagement, all of these still come due, but later. Programs that pause investment will hit a notified-body capacity wall in late 2027 because the deadline compresses the assessment workload.
  • GPAI enforcement still arrives Aug 2, 2026. If your stack uses GPAI models (most stacks do), your vendor due diligence, your Annex XII documentation, your Article 53(1)(c) copyright policy review, and your Article 53(1)(d) public training-data summary review are all on the original timeline.
  • Article 50 watermarking accelerates. The Article 50(2) machine-readable marking grace period was cut, bringing watermarking obligations forward to Dec 2, 2026. Procurement contracts for generative-image and generative-video vendors need C2PA / SynthID / IPTC marking commitments now.
  • Article 5 prohibitions are already in force. They have been since Feb 2, 2025. The negative-assurance review across the inventory does not wait for Aug 2, 2026.
  • Article 4 literacy is already in force. Same Feb 2, 2025 date. The literacy curriculum should already be operational by May 2026.
  • The Omnibus regulation must still be formally adopted and published in the Official Journal before Aug 2, 2026 to take effect. Until then, prudent programs plan for both timelines.

The cost of an Omnibus-VII-aware tiering memo is exactly the cost of three additional columns in the spreadsheet: "applicability date pre-Omnibus," "applicability date post-Omnibus," "still-applies-Aug-2026." The board director who asks "what changed?" gets an immediate answer.

The Article 6(3) Narrow-Task Carve-Out

Article 6(3) is the most-misused provision in the entire risk-tier framework. It provides that an AI system referred to in Annex III shall not be considered high-risk if it does not pose a significant risk of harm to the health, safety, or fundamental rights of natural persons because it meets one of four narrow conditions:

  • The system is intended to perform a narrow procedural task.
  • The system is intended to improve the result of a previously completed human activity.
  • The system is intended to detect decision-making patterns or deviations from prior decision-making patterns, and is not meant to replace or influence the previously completed human assessment, without proper human review.
  • The system is intended to perform preparatory tasks for an assessment relevant for an Annex III use case.

The carve-out is provider-self-assessed. The provider documents the rationale, registers the system under Article 49(2) in the EU database (registering that the system is in an Annex III category but the carve-out applies), and bears the burden of demonstrating the analysis on regulator request. Important: the carve-out collapses if the system performs profiling of natural persons. Profiling automatically forfeits the carve-out, full stop.

The common abuse pattern: a deployer of an HR-screening tool argues "it's just a preparatory task, the recruiter makes the final decision." But the system profiles natural persons by definition. The carve-out does not apply. The memo should not embarrass itself by claiming a carve-out that the regulation explicitly forecloses.

Where 6(3) does legitimately apply: an Annex III §5(a) public-assistance triage tool that exclusively sorts incoming applications by completeness (a "narrow procedural task" with no profiling). An Annex III §3 education tool that surfaces a previously human-written rubric ("improve the result of a previously completed human activity") without scoring the student. A spell-check inside a high-risk system. A spreadsheet sort. Article 6(3) is real, but its scope is narrower than vendor marketing material suggests.

Floor 3 - The Article 50 Limited / Transparency Tier

Article 50 lays out the transparency obligations for systems that do not rise to high-risk but still warrant user-facing disclosure. The four sub-articles cover four distinct trigger conditions, and they apply regardless of risk tier, a system can be Annex III high-risk and also trigger Article 50 disclosure obligations on top.

  • Article 50(1): AI systems intended to interact directly with natural persons must be designed so that the affected persons are informed they are interacting with an AI system, in a clear and distinguishable manner, at the latest at the time of the first interaction. (Exceptions: where it is obvious from the circumstances, or for law enforcement under specific safeguards.) The canonical case: chatbots, voice agents, AI receptionists.
  • Article 50(2): Providers of AI systems generating synthetic audio, image, video, or text content shall ensure that the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The Omnibus VII political agreement cut the grace period, bringing this obligation forward to Dec 2, 2026. Compatible technical standards: C2PA, SynthID, IPTC photo metadata.
  • Article 50(3), Deployers of emotion-recognition systems and biometric-categorization systems shall inform natural persons of their operation (with limited carve-outs).
  • Article 50(4): Deployers of AI systems generating or manipulating image, audio, or video content constituting a "deep fake" shall disclose that the content has been artificially generated or manipulated. Carve-outs for artistic, satirical, fictional works. For text intended to inform the public on matters of public interest, an additional disclosure is required.

The practical implication: every Article 50 trigger is a column in the spreadsheet alongside the high-risk classification. Most consumer-facing AI products will have at least one Article 50 column lit up, even if the high-risk column is dark. A customer-service chatbot is Article 50(1). A marketing-generative-image tool is Article 50(2) and Article 50(4). An employee-engagement emotion-analysis tool is Article 5(1)(f) prohibited (workplace) or Article 50(3) limited (consumer). The tiering memo should make all four sub-articles explicit, with the trigger condition named per system.

Floor 4 - The Residual Minimal-Risk Tier

Anything that clears the prohibited check, does not land in Annex I or Annex III, and does not trigger Article 50, is minimal-risk by residue. The minimal-risk tier carries three obligations directly:

  • Article 4 AI literacy. All providers and deployers must take measures to ensure a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of the AI system on their behalf, taking into account technical knowledge, experience, education, training, the context, and the persons or groups on whom the system is to be used.
  • Article 95 voluntary codes of conduct. The Commission and Member States encourage minimal-risk providers to apply, voluntarily, the high-risk requirements where appropriate. This is a hook for organizations choosing to commit beyond the legal minimum.
  • The horizontal regulatory overlay. Minimal-risk under the AI Act does not exempt the system from GDPR, the Digital Services Act, the Digital Markets Act, sectoral rules, or national consumer law. The AI Act tiering does not collapse those obligations.

The audit-committee question hiding here: "How big is our minimal-risk bucket?" If the answer is "we don't know," the inventory is incomplete. If the answer is "47 systems," the next question is whether the literacy program reaches all 47. Minimal-risk is not invisible. It is the largest bucket in most enterprises, and Article 4 makes it auditable.

The Tiering Memo Template - What the AI Officer Actually Reads

The tiering memo is the L1 artifact. It is a structured table with a per-system rationale paragraph, citation columns to Article 5, Article 6, Annex III, Article 50, and a workflow column ("operational owner," "next review," "open obligations"). Here is the template, with one row filled in for a representative case:

System: Acme.HR Resume Ranker (vendor: Workday Talent Acquisition AI, Q1 2026 release)
Article 3(1) scope: In scope. Embedding-based ranker; provenance test passes; outputs influence the recruiter's shortlist.
Article 5 prohibited check: Negative. The system is not subliminal manipulation (5(1)(a)), does not exploit vulnerabilities (5(1)(b)), is not social scoring (5(1)(c)), is not predictive policing (5(1)(d)), is not untargeted scraping (5(1)(e)), is not workplace emotion recognition (5(1)(f)), distinct from candidate-scoring use, which is Annex III §4 high-risk, not 5(1)(f) prohibited, is not protected-attribute biometric categorization (5(1)(g)), is not real-time biometric ID (5(1)(h)).
Article 6 high-risk check: Annex III §4 employment, high-risk. (Article 6(1) Annex I embedded-product, not applicable.)
Article 6(3) carve-out: Not applicable. The system performs profiling of natural persons (candidate ranking based on inferred features), which automatically forfeits the carve-out per Article 6(3).
Article 50 transparency check: Article 50(1) chatbot disclosure not triggered (no user-facing dialogue). Article 50(2) synthetic-content marking not triggered. Article 50(4) deepfake disclosure not triggered.
Applicability date: Pre-Omnibus VII - Aug 2, 2026. Post-Omnibus VII - Dec 2, 2027 (stand-alone Annex III). GPAI obligations on upstream provider, Aug 2, 2026 unchanged.
Open obligations: Article 9 RMS, Article 10 data governance, Article 11 + Annex IV technical file, Article 14 human oversight, Article 15 accuracy/robustness/cybersecurity claims, Article 17 QMS (provider-side; flow-down to deployer through Article 13 information), Article 26 deployer obligations, Article 27 FRIA (Acme is a private operator providing public services in some Member States; FRIA required where applicable), Article 47 declaration of conformity (vendor), Article 71 EU database registration, Article 72 post-market monitoring, Article 73 reporting clock.
U.S. overlay: NYC LL 144 AEDT, applicable; annual bias audit and 10-business-day candidate notice required. Texas TRAIGA HB 149, applicable for Texas-domiciled candidates; intentional-discrimination prohibition. Colorado SB 24-205: currently stayed (federal court, Apr 27, 2026); monitor SB 189 replacement.
Operational owner: Head of Talent Acquisition; risk partner, Responsible AI Officer.
Next review: Quarterly + triggered on vendor model update.

Notice three properties of the template. First, every gate is named explicitly: Article 5 sub-paragraph by sub-paragraph, Article 6 sub-article by sub-article, Article 50 sub-article by sub-article. A regulator does not have to guess which gates were considered. Second, the carve-out (Article 6(3)) is addressed and rejected with the regulatory reason, "profiling of natural persons forfeits the carve-out." Third, the dual-applicability columns ("pre-Omnibus, post-Omnibus, still-applies-Aug-2026") let the audit committee see exactly what changed and what did not.

The Ten-System Tour - Walking the Tiering Sequence

Apply the sequence to ten representative enterprise systems and you produce, in an afternoon, the tiering register that anchors L1 through L5:

  1. Customer-service chatbot (Anthropic Claude under the hood). Article 5, negative. Article 6, no Annex III hit. Article 6(3), not applicable (no Annex III). Article 50(1), triggered (interacts with natural persons). Tier: limited / transparency. Open obligations: Article 50(1) chatbot notice; Article 4 literacy for the customer-service org; Article 26 deployer logging where downstream agent actions are taken.
  2. Spreadsheet formula for monthly forecast. Out of scope under Article 3(1). No tier, not in inventory beyond a "scope-tested out" entry.
  3. Power BI Smart Insights dashboard. Article 5, negative. Article 6, no Annex III. Article 50, not triggered (not interacting with natural persons in the Article 50(1) sense; not generating synthetic content). Tier: minimal-risk. Article 4 literacy applies.
  4. XGBoost fraud-detection model (in-house) feeding creditworthiness decisions at a regulated bank. Article 5, negative. Article 6 - Annex III §5(b) credit. Article 6(3), not applicable (profiling). Tier: high-risk Annex III §5(b). FRIA required under Article 27 for the credit deployer.
  5. HR resume ranker (Workday). Article 5, negative. Article 6 - Annex III §4 employment. Article 6(3), not applicable. Tier: high-risk Annex III §4. NYC LL 144 + Texas TRAIGA overlays.
  6. Marketing-segmentation k-means clusterer. Article 5, negative. Article 6, no Annex III. Article 50, not triggered. Tier: minimal-risk. Article 4 literacy applies. (If used to deduce protected attributes, 5(1)(g) would fire, but standard CRM behavioral segmentation does not.)
  7. Generative-image marketing tool (Adobe Firefly, Midjourney, etc.). Article 5, negative. Article 6, no Annex III. Article 50(2), triggered (synthetic-image generation; Dec 2, 2026 marking obligation). Article 50(4), triggered for any deepfake imagery of natural persons. Tier: limited / transparency. C2PA / SynthID marking required.
  8. Internal coding assistant (Copilot Enterprise). Article 5, negative. Article 6, no Annex III. Article 50(1), not triggered (developer-IDE plug-in; Recital context shows obviousness exception applies). Article 50(2), debated for generated code; safe-harbor practice is to mark generated code in commit metadata. Tier: minimal-risk (with a defensible argument for limited under 50(2) on safe-harbor practice). Article 4 literacy for the engineering org.
  9. Retail-analytics camera that classifies customer age band and dwell time. Article 5(1)(g): protected-attribute biometric-categorization risk (if the system deduces race, religion, etc., the practice is prohibited). Standard age-band categorization is not Article 5(1)(g) prohibited but is Annex III §1 biometric high-risk for emotion-recognition or remote biometric identification components. Tier: high-risk Annex III §1 unless narrowly carved out under 6(3); rare. Substantial GDPR overlay.
  10. Smart-grid load-balancing AI (safety component). Article 6(1) Annex I embedded product, yes if the underlying product is covered by harmonized legislation with third-party conformity assessment. Annex III §2 critical infrastructure also potentially applies if standalone. Tier: high-risk Annex I (Aug 2, 2028 applicability) or Annex III §2 (Dec 2, 2027), depends on packaging.

Ten rows, ten tier classifications. Two prohibited-tier exposures avoided. Four high-risk systems flagged for FRIA, Annex IV, and notified-body queues. Two limited-tier flagged for Article 50 disclosures. Two minimal-risk flagged for Article 4 literacy. One out-of-scope removed. That is what the AI Officer expects to see on Monday morning.

Mapping the Penalty Exposure - Article 99

Each tier carries a different worst-case penalty exposure. The audit committee asks: "What is the maximum we could pay if this goes wrong?" The answer comes from Article 99:

  • Article 99(2), Article 5 prohibited-practice violations: up to €35 million or 7% of worldwide annual turnover (whichever is higher).
  • Article 99(3): Most provider failures (high-risk, GPAI, etc.) including Article 16 provider obligations: up to €15 million or 3%. Article 73 serious-incident reporting failures sit here.
  • Article 99(4), Specific obligations on operators and notified bodies, except those covered by 99(3) and 99(5): up to €15 million or 3%.
  • Article 99(5): Supply of incorrect, incomplete, or misleading information to notified bodies and competent authorities: up to €7.5 million or 1%.
  • SMEs / start-ups, Member States are required to take into account SME and start-up interests and may apply the lower of the fixed amount or the percentage where appropriate.
  • National implementation, Some Member States have national implementing law adding additional administrative or criminal exposure on top.

The tiering memo should show penalty exposure per row. For a Fortune-500 with €20 billion in global turnover, exposure on a single prohibited-practice violation is €1.4 billion. The same firm's Article 73 reporting-failure exposure is €600 million. These numbers travel fast through the audit committee and the board, and they create the budget that lets the Responsible AI Officer hire two more people.

Common Tiering Mistakes - And How to Catch Them

Mistake 1 - Confusing Article 5(1)(f) Workplace Emotion-Recognition Prohibition with Annex III §4 Employment High-Risk

Article 5(1)(f) prohibits emotion recognition in workplaces and educational institutions (with narrow medical/safety carve-outs). Annex III §4 covers employment-related high-risk AI more broadly (resume screening, performance evaluation, allocation of tasks). The two regimes overlap: a tool that uses emotion recognition to evaluate employee performance is both Article 5(1)(f) prohibited and Annex III §4 high-risk. The dominant classification is prohibited, Article 5 takes precedence. The tiering memo should call out the dominant classification explicitly.

Mistake 2 - Claiming the Article 6(3) Carve-Out for Systems That Perform Profiling

Profiling automatically forfeits the carve-out. An HR-screening tool is profiling per GDPR Article 4(4). Carve-out unavailable. The vendor sales pitch that "our tool just helps the recruiter, Article 6(3) applies" is a sales pitch, not a legal opinion.

Mistake 3 - Treating Article 50 as Mutually Exclusive with High-Risk

It is not. Article 50 disclosure obligations apply on top of any high-risk obligations. A biometric-categorization system that is Annex III §1 high-risk is also Article 50(3) limited, both apply.

Mistake 4 - Skipping the Annex I Check

Most enterprise programs skip Article 6(1) Annex I because "we don't make machinery." But Annex I covers a long list of harmonized-product legislation, including medical devices, in-vitro diagnostic devices, and pressure equipment. A hospital deploying an AI-based clinical-decision-support system that integrates into a CE-marked in-vitro diagnostic instrument is on the Annex I track, not the Annex III track. The applicability date is Aug 2, 2028 post-Omnibus VII. Missing this changes the program's spend cadence.

Mistake 5 - Continuing to Budget Against the Pre-Omnibus Timeline

The Omnibus VII political agreement moved the stand-alone Annex III date to Dec 2, 2027 and Annex I to Aug 2, 2028. Programs continuing to budget against Aug 2, 2026 for Annex III over-spend in 2026 and risk a budget cut in 2027 just when the notified-body capacity crunch arrives. Conversely, programs that cut 2026 spending entirely lose the GPAI-enforcement readiness work that is still due Aug 2, 2026. The right move is a re-baselined two-year roadmap that keeps GPAI-readiness on the original track and re-times the Annex III artifacts against Dec 2, 2027.

Mistake 6 - Treating the Tier Classification as Static

A system that is minimal-risk today becomes high-risk when its operator adds a feature, use case, or deployment context. The tiering memo is a living document. Quarterly review plus triggered updates on vendor model change, scope expansion, fine-tuning, and new deployment context. Trigger events mirror those for the scope memo.

Aligning the Tiering Memo With ISO 42001 and NIST AI RMF

ISO/IEC 42001:2023 Annex A control A.6.2, AI system impact criteria, explicitly requires the organization to define criteria for assessing the impact of AI systems on individuals, groups, and society, and to document the impact level. The tiering memo is the A.6.2 artifact. NIST AI RMF 1.0 function Map 2 ("Categorization of the AI system is performed") similarly requires categorizing the AI system per its intended use and contextual risk. The same memo satisfies both, Article 5 / 6 / Annex III / 50 columns serve EU; impact-level and use-case categorization serve ISO 42001 A.6.2 and NIST AI RMF Map 2 simultaneously.

This is the same dual-citation pattern from the scope memo. Write the analysis once, cite it three times. Audit cost, documentation drift, and auditor surprise all go down.

Key Takeaways

  • Risk-tier classification is the elevator. Four floors, prohibited, high-risk, limited / transparency, minimal-risk, each with a wildly different bill of materials. The tier decision sets the budget.
  • The sequence matters. Five questions in order: Article 5 prohibited? Article 6(1) Annex I? Article 6(2) Annex III? Article 6(3) carve-out? Article 50 transparency? Answer "yes" to the first and stop; "no" to all five and you land in minimal-risk.
  • Article 5 has eight prohibited categories. Most enterprise prohibited-tier exposure comes from vendor-bundled emotion AI, manipulative engagement features, and biometric categorization. The negative-assurance review is the cheapest insurance the organization buys.
  • Annex III has eight high-risk categories. Biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice and democratic processes. Employment is the biggest enterprise category by far.
  • Omnibus VII moved the deadlines but did not eliminate the obligations. Stand-alone Annex III moved to Dec 2, 2027. Annex I embedded products to Aug 2, 2028. Article 50 watermarking accelerated to Dec 2, 2026. GPAI enforcement remained Aug 2, 2026. Article 5 prohibitions and Article 4 literacy have been in force since Feb 2, 2025.
  • Article 6(3) is misused. The narrow-task carve-out applies in narrow cases and collapses on profiling. Most HR-tech and credit-scoring vendor claims to the carve-out are unsupportable.
  • Article 50 stacks on top. A system can be both high-risk and limited / transparency. The tiering memo must address Article 50 separately from the high-risk classification.
  • Article 99 penalty exposure is real. Up to €35M or 7% of global turnover for Article 5; up to €15M or 3% for most provider failures; up to €7.5M or 1% for misleading information. Map penalty exposure per row of the tiering memo.
  • The tiering memo is the L1 artifact. Structured table, citation columns to every relevant article, operational owner, next-review date, and a per-row rationale paragraph. The AI Officer, the General Counsel, and the notified body read it on the same day.
  • Tier classification is living. Quarterly review plus triggered updates on vendor changes, scope expansion, fine-tuning, and new deployment contexts. The same memo doubles as ISO 42001 A.6.2 evidence and NIST AI RMF Map 2 artifact.